Privacy and encryption

whodar treats the people graph it builds as sensitive by construction. It runs on your machine, keeps the index on your disk, can encrypt that index at rest, and controls exactly what any AI model is allowed to see. This page collects those guarantees in one place.

Where your data lives

Encrypt the index at rest

File permissions alone do not protect the index from a stolen disk, a stray backup, or another process running as you. Configure a key and whodar encrypts the index on every write and decrypts it on every read.

Two ways to supply the key:

# a base64 32-byte key, best for automation and servers
export WHODAR_INDEX_KEY=$(whodar vault keygen | sed 's/^export [^=]*=//')

# or a passphrase, prompted if unset when you run on a terminal
export WHODAR_INDEX_PASSPHRASE='a long passphrase'

With a key set, whodar index writes an encrypted file and every read decrypts it. The contents are sealed with AES-256-GCM, which authenticates the data so tampering is detected. A passphrase is stretched into a key with Argon2id and a per-file salt.

Manage it with the vault command:

whodar vault keygen     # print a fresh export line to save
whodar vault status     # is a key configured, is the index encrypted
whodar vault encrypt    # encrypt an existing plain index in place
whodar vault decrypt    # rewrite it back to plain JSON

Two things to know:

Control what a model sees

Answers are computed locally by default. When you opt into an AI model, an egress policy governs exactly what leaves the machine. The default is strict, and an administrator can pin the policy in a file that user flags and environment variables cannot loosen.

Mode What leaves the machine
strict Nothing. Only the keyword engine and a local model are allowed.
redacted The question and anonymized numbered candidates: title, team, and matched terms. Never names, emails, channel names, or message text. whodar re-maps the numbers to real people locally.
open Full candidate detail, for teams that accept it and choose their own model.

Local models through Ollama need no opt-in, since they run on hardware you control. Cloud models (Claude, Gemini, OpenAI) run only when you turn them on and only to their known hosts.

On the roadmap

The roadmap carries this further: separating identities from ranking signal so redaction becomes structural rather than a filter, and a zero-knowledge design for the planned hosted tier so a managed whodar could store only ciphertext it cannot read.